Описание
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2.5.1+dfsg-1ubuntu0.1 |
| cosmic | ignored | end of life |
| devel | not-affected | 2.7.7+dfsg-1 |
| disco | not-affected | 2.7.7+dfsg-1 |
| esm-apps/bionic | released | 2.5.1+dfsg-1ubuntu0.1 |
| esm-apps/xenial | not-affected | code not present |
| esm-infra-legacy/trusty | not-affected | code not present |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | not-affected | code not present |
Показывать по
EPSS
3.3 Low
CVSS2
4.2 Medium
CVSS3
Связанные уязвимости
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path ...
Уязвимость модуля fetch системы управления конфигурациями Ansible, связанная c неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность
EPSS
3.3 Low
CVSS2
4.2 Medium
CVSS3